If you see an “Update NSP” labeled as XCOM 2 Collection [Update][v1.0.4][eShop] , it is legitimate only if you already own the base game legally.
Play docked with a Pro Controller, avoid Ironman mode (due to save corruption risks in early updates), and manually save often.